Skip to content

feat(project): add BedrockManagedAgents template support - #2484

Merged
nborges-aws merged 9 commits into
refactorfrom
bma-support
Sep 30, 2026
Merged

nborges-aws merged 9 commits into
refactorfrom
bma-support

Conversation

@nborges-aws

Copy link
Copy Markdown
Contributor

Description

Adds Bedrock Managed Agents (BMA) support to the v1 AgentCore CLI

Scaffold a BMA execution environment with:

agentcore create --name MyManagedAgent --template bedrock-managed-agent
  • Adds a bedrock-managed-agents runtime template for CLI and TUI project creation
  • Includes BMA container, lifecycle server, sample client, observability configuration, example skill, and Mantle IAM policy asset
  • Generates the required Runtime configuration:
    • lifecycle/server.py entrypoint
    • container build configuration
    • BMA lifecycle timeout defaults
    • Mantle permissions
    • identifying BMA tag
  • Skips local Python dependency installation because dependencies are installed while building the container
  • Warns when an existing execution role is supplied, since the generated Mantle policy cannot be attached automatically
  • Rejects BMA creation, addition, and deployment in China region
  • Updates README documentation
  • Adds test coverage for configuration, lifecycle behavior, region restrictions, warnings, and profile resolution

Type of Change

  • Bug fix
  • New feature
  • Breaking change
  • Documentation update
  • Other (please describe):

Testing

How have you tested the change?

  • bun run test (3949 pass, 0 fail)
  • I ran npm run test:unit and npm run test:integ
  • I ran npm run typecheck
  • I ran npm run lint
  • If I modified src/assets/, I ran npm run test:update-snapshots and committed the updated snapshots

Checklist

  • I have read the CONTRIBUTING document
  • I have added any necessary tests that prove my fix is effective or my feature works
  • I have updated the documentation accordingly
  • I have added an appropriate example to the documentation to outline the feature, or no new docs are needed
  • My changes generate no new warnings
  • Any dependent changes have been merged and published

By submitting this pull request, I confirm that you can use, modify, copy, and redistribute this contribution, under the
terms of your choice.

@nborges-aws nborges-aws changed the title Bma support feat(project): add BedrockManagedAgents template support Sep 30, 2026
@github-actions github-actions Bot added size/xl PR size: XL and removed size/xl PR size: XL labels Sep 30, 2026
@agentcore-devx-automation agentcore-devx-automation Bot added agentcore-harness-reviewing AgentCore Harness review in progress claude-security-reviewing Claude Code /security-review in progress labels Sep 30, 2026
Comment thread README.md Outdated
Comment on lines +45 to +56
To create an execution environment for Bedrock Managed Agents:

```bash
agentcore create --name MyManagedAgent --template bedrock-managed-agents
```

Bedrock Managed Agents runs the agent loop and sends lifecycle and command requests to the
generated AgentCore Runtime. The Runtime is a container environment for Codex rather than an agent
that invokes a model itself, so it has no model-provider or memory configuration. Its dependencies
are installed when the container image is built. The generated Runtime README covers deployment,
the sample client, persistence, observability, and adding skills.

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

lets remove this from the readme since it's specific to this feature

@agentcore-devx-automation

Copy link
Copy Markdown
Contributor

Claude Security Review: no high-confidence findings. (run)

@agentcore-devx-automation agentcore-devx-automation Bot removed claude-security-reviewing Claude Code /security-review in progress agentcore-harness-reviewing AgentCore Harness review in progress labels Sep 30, 2026
Comment thread src/handlers/project/shortcuts.ts Outdated
},
"bedrock-managed-agents": {
runtimeName: "bedrock_managed_agents",
description: "Codex execution environment for Bedrock Managed Agents",

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

is it worded "codex execution environment" officially?

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I'll remove codex to be safe

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actually I think it is throughout. Let's confirm if this was also the wording in the merge in main line

@codecov-commenter

codecov-commenter commented Sep 30, 2026 •

Copy link
Copy Markdown

Codecov Report

❌ Patch coverage is 99.55947% with 1 line in your changes missing coverage. Please review.
✅ Project coverage is 97.39%. Comparing base (1fd3ac0) to head (cc674fa).

Files with missing lines Patch % Lines
src/core/project/templates/runtime.ts 98.70% 1 Missing ⚠️
Additional details and impacted files
@@            Coverage Diff             @@
##           refactor    #2484    +/-   ##
==========================================
  Coverage     97.39%   97.39%            
==========================================
  Files           638      642     +4     
  Lines         46622    46807   +185     
==========================================
+ Hits          45406    45590   +184     
- Misses         1216     1217     +1     

☔ View full report in Codecov by Harness.
📢 Have feedback on the report? Share it here.

🚀 New features to boost your workflow:
  • ❄️ Test Analytics: Detect flaky tests, report on failures, and find test suite problems.
  • 📦 JS Bundle Analysis: Save yourself from yourself by tracking and limiting bundle sizes in JS merges.

@github-actions github-actions Bot added size/xl PR size: XL and removed size/xl PR size: XL labels Sep 30, 2026
@agentcore-devx-automation agentcore-devx-automation Bot added the claude-security-reviewing Claude Code /security-review in progress label Sep 30, 2026
@agentcore-devx-automation

Copy link
Copy Markdown
Contributor

Claude Security Review: no high-confidence findings. (run)

@agentcore-devx-automation agentcore-devx-automation Bot removed the claude-security-reviewing Claude Code /security-review in progress label Sep 30, 2026

@notgitika notgitika left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Great work! Left a comment which doesn't have to be addressed right away.

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

https://docs.aws.amazon.com/bedrock/latest/userguide/inference-responses-api.html

Not sure if we'd wanna add some validation here but Mantle has a region allowlist. For instance I could put in us-west-1 which will result in failing sessions (create and deploy will pass). But adding this client side validation will result in us maintaining the code.

What do you think? Maybe we add it in our docs or in the scaffolded template readme? a statement like "Please verify you are using a supported region" and link to these docs

@tejaskash tejaskash left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

No actionable regressions found. All 3,949 tests passed, along with typechecking, linting, the CLI build, and the generated Docker build. Live BMA session behavior was not verified.

@nborges-aws
nborges-aws merged commit 04b45c3 into refactor Sep 30, 2026
20 checks passed
@nborges-aws
nborges-aws deleted the bma-support branch September 30, 2026 20:33

@Hweinstock Hweinstock left a comment •

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I'm still generally confused about how a customer is expected to use this, but I see this is merged, so will continue offline.

@@ -0,0 +1,26 @@
import type { RuntimeTemplateProfile } from "./templateProfile";

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

more general comment, but is there a way to centralize the bma logic a single place? I feel like we're special casing in a few different places.

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

For getting this up and running; the special casing was pretty necessary. This file holds as much centralized logic as made sense for a first pass. The special casing elsewhere is in cases where metadata is only available at that layer and not persisted, for example.

We likely could improve the centralization, but that's a separate effort from the generic support logic this PR holds imo.

@@ -0,0 +1,69 @@
# The CloudWatch agent runs this OpenTelemetry Collector configuration. It receives OTLP from

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

i thought runtime did some of this for us?

supportsModelProviderOverride: false,
runtimeVersion: "NODE_22",
},
"bedrock-managed-agents": {

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

my understanding is that this template is actually an execution environment for an agent, but this name suggests that it is itself an agent? Is this template also including some code to set up that agent?

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Yeah it is an exec env for the agent; not the agent itself. But the name does indicate the service that the template is supporting. I do see how it could be a bit confusing

build: BuildTypeSchema,
language: z.enum(["Python", "TypeScript"]),
framework: z.enum(["strands", "langchain", "vercelai", "none"]),
framework: z.enum(["strands", "langchain", "vercelai", "bedrock-managed-agents", "none"]),

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I'm not sure this fits as a framework.

@@ -0,0 +1,35 @@
import { isChinaRegion } from "../../../core/partition";

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

how exactly is this change related to the goal of shipping the template?

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Before this PR, the region validation existed only in the CLI handlers. The TUI called ProjectManager.create(), which was sidestepping the CN region check completely. This wasn't only a BMA issue but a widespread one. Specifically for BMA, the CN checks are needed since bedrock/mantle isn't available in CN.

I added this file so we could use the logic to exercise the region checks in both CLI and TUI flows before calling create.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

size/xl PR size: XL

Projects

None yet

Development

Successfully merging this pull request may close these issues.

5 participants